Skip to content

chore: add canonical SECURITY.md#23

Merged
stackbilt-admin merged 1 commit intomainfrom
chore/add-security-md
Apr 10, 2026
Merged

chore: add canonical SECURITY.md#23
stackbilt-admin merged 1 commit intomainfrom
chore/add-security-md

Conversation

@stackbilt-admin
Copy link
Copy Markdown
Member

Summary

Adds the standardized Stackbilt-dev SECURITY.md to this repository. This is the canonical per-repo security reporting file being rolled out across the entire Stackbilt-dev organization, so every repository exposes the same reporting entry point, response SLAs, and scope definition.

What this adds

  • Primary reporting channel: admin@stackbilt.dev with SECURITY: subject prefix
  • GitHub Security Advisory link scoped to this repo for coordinated disclosure
  • Response target matrix — Critical: 24h ack / 7d fix; High: 48h / 14d; Medium/Low: 5 business days / next release
  • Explicit "no public GH issues for vulnerabilities" rule — external researchers should not open public issues for security findings
  • Scope and out-of-scope sections clarifying what's covered (e.g., DoS on free tier is explicitly out of scope — Cloudflare handles DDoS)
  • Coordinated disclosure terms — 90-day window (30 days for critical), credit in release notes, no legal action against good-faith researchers
  • Link back to the canonical policy at https://docs.stackbilt.dev/security/

Why this matters

Every Stackbilt-dev repository should have a SECURITY.md so the GitHub security tab surfaces it automatically and external researchers have a clear, consistent reporting path. Without a per-repo file, researchers either open public issues (which is the wrong channel and leaks the vulnerability) or give up and don't report at all.

Test plan

Related


🤖 Generated with Claude Code

Adds the standardized Stackbilt-dev security reporting template to this
repository. The template is the canonical per-repo security file rolled
out across the entire Stackbilt-dev organization as part of the outbound
disclosure policy (Stackbilt-dev/docs#15).

Key points:
- Primary reporting channel: admin@stackbilt.dev
- GitHub Security Advisory link scoped to this repo
- Response target matrix (critical 24h ack / 7d fix, high 48h / 14d)
- Full policy link at https://docs.stackbilt.dev/security/
- Explicit "do not open public GH issues for vulns" rule

This replaces the implicit policy that existed via the Stackbilt-dev
organization profile with an explicit per-repo file, so the GitHub
security tab surfaces it and external researchers have a clear
reporting path.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@stackbilt-admin stackbilt-admin merged commit e99a650 into main Apr 10, 2026
@stackbilt-admin stackbilt-admin deleted the chore/add-security-md branch April 10, 2026 12:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant